Your car’s software update is supposed to fix problems, not quietly recruit its infotainment system into a botnet.
Kaspersky publicly disclosed the campaign on Aug. 21 after its researchers uncovered malware spreading through the legitimate update mechanism used by some Android-based car head units. The malware can be installed on affected infotainment systems without requiring drivers to install anything, and then used to commit ad fraud and as part of a proxy botnet.
Kaspersky’s findings suggest the issue is limited to specific Android-based head units, not to Android Auto or Android-powered vehicles as a whole. Researchers traced the campaign to head units via software from the Chinese automotive technology provider DoFun, which used compromised update channels to deliver malware.
Malware arrives through a legitimate update app
Kaspersky researchers discovered the campaign in June while investigating an unusual Android application called JarService. Unlike typical Android malware, it had no user interface and did not rely on tricking users into installing it because it was already embedded in the head unit’s firmware.
JarService was delivered through TWCore, a legitimate system application that manages software updates on affected DoFun head units. Attackers abused this trusted update channel to distribute malware without requiring any user action.
Kaspersky described the campaign as the first documented case of malware delivered to automotive head units via an automated firmware update service. DoFun told Kaspersky that the issue responsible for the distribution of malicious software has since been fixed.
The attack resembles a broader security problem enterprises have confronted with other trusted software channels. Earlier this year, attackers hijacked the Notepad++ update infrastructure to distribute malicious installers, demonstrating how a standard update process can become an attack vector when its underlying infrastructure is compromised.
Infected cars become part of a proxy botnet
JarService is only the first stage.
Once installed, the malware decrypts and launches another loader that contacts an attacker-controlled command-and-control server to retrieve additional payloads. One of those payloads can generate fraudulent advertising activity, while the other can add the infected head unit to a proxy network.
According to Kaspersky’s analysis of the campaign, infected systems can send information including their device model, screen resolution, MAC address, and connected Wi-Fi network to the attackers. The malware can receive commands to make HTTP requests, open webpages, and download and execute additional malicious code.
Researchers linked the activity to MoYu Group, a threat actor associated with the BADBOX malware ecosystem. Kaspersky also found links between MoYu Group and residential proxy services that allow customers to route internet traffic through devices connected to the botnet.
That means the target is not necessarily the data stored in the car. The vehicle itself becomes valuable infrastructure.
Android’s flexibility helps manufacturers build highly customized infotainment systems, but it also gives attackers another familiar operating environment to target. Mobile threats have already pushed well beyond conventional malicious apps. The recently discovered Manic Android malware can relay stolen information through nearby infected phones, while Google has also had to patch Android vulnerabilities already being exploited in attacks.
What drivers and security teams should know
Kaspersky found no evidence that the malware could control critical vehicle functions such as steering, braking, or acceleration. The campaign targeted Android-based infotainment head units and used their internet connections for malicious activity.
The impacted systems also represent only a subset of the automotive market. DoFun develops firmware, applications and cloud services for Android-based automotive head units and says its products serve more than 30 million vehicle owners worldwide, but Kaspersky has not said that all of those devices were compromised.
This attack shows how weaknesses in the software supply chain can extend to connected vehicle systems.
Modern vehicles rely on internet-connected hardware, third-party software, and automated updates, increasing the overall attack surface area. Security teams managing vehicle fleets should include infotainment and other connected systems in asset inventories, network monitoring, and third-party risk assessments.
For drivers, unexpected apps or unusual network activity on an Android-based head unit should be treated as potential signs of compromise.
As more vehicle systems become connected, manufacturers and fleet operators need to account for the security risks that come with third-party software and update mechanisms. The DoFun campaign shows how compromising one of those trusted channels can turn vehicle hardware into part of a botnet.
Also read: Manic Android malware can steal banking credentials and relay stolen data through nearby infected phones, showing how mobile threats are finding new ways around traditional defenses.





